เครือข่าย/HTTP
Email Header Analyzer
แยกวิเคราะห์ส่วนหัวดิบของอีเมล (View Source / Show Original) — ฟิลด์พื้นฐาน ลำดับ Received พร้อมเวลา SPF/DKIM/DMARC สัญญาณการปลอมแปลง From/Reply-To
A message's full headers (View Source or Show Original in a mail client) record its entire path through mail servers, along with sender-authenticity check results. This tool breaks those headers down into readable fields and flags signs of spoofing.
How to use it
- Paste raw email headers and the tool extracts the main fields (From, To, Subject, Date) along with the Received chain and the timing of each hop.
- SPF, DKIM, and DMARC results are shown separately with an explanation of what each status (pass, fail, none) means.
- A mismatch between the From and Reply-To headers is flagged — a common sign of phishing.
Common uses
- Checking a suspicious email for signs of phishing before trusting its links or attachments.
- Debugging why a legitimate email lands in spam by checking its SPF/DKIM/DMARC status.
- Tracing an email's actual path through servers to understand a delivery delay.
Things to keep in mind
The Date header is set by the sender's client and can be inaccurate; for an exact timeline, trust the timestamps in the Received chain, which are added by the mail servers themselves.
Passing SPF/DKIM/DMARC only confirms the message is technically authorized by the sending domain — it doesn't guarantee the content itself isn't phishing or spam.
บทความเกี่ยวกับเครื่องมือนี้: Email Headers: SPF, DKIM และ DMARC ตรวจสอบผู้ส่งจริงอย่างไร
คำถามที่พบบ่อย
เฮดเดอร์อีเมลบอกอะไรฉันได้จริง ๆ ที่เนื้อหาข้อความบอกไม่ได้?
เฮดเดอร์เผยเส้นทางที่อีเมลผ่านเซิร์ฟเวอร์เมล (บรรทัด Received) ผลการยืนยันตัวตน (SPF, DKIM, DMARC) และเซิร์ฟเวอร์ต้นทางที่แท้จริง — มีประโยชน์ในการตรวจจับอีเมลปลอมหรือฟิชชิง
จะรู้ได้อย่างไรว่า SPF, DKIM หรือ DMARC ผ่านจริง?
มองหา pass, fail หรือ none ในเฮดเดอร์ Authentication-Results — "pass" ทั้งสามตัวเป็นสัญญาณที่ชัดเจน (แม้จะไม่แน่นอนทั้งหมด) ว่าข้อความไม่ถูกปลอมแปลง ในขณะที่การล้มเหลวในการตรวจสอบที่สำคัญต่อผู้ส่งเป็นสัญญาณเตือน
การวางเฮดเดอร์อีเมลที่นี่อัปโหลดมันไปที่ไหนหรือไม่?
ไม่ เฮดเดอร์ถูกแยกวิเคราะห์ทั้งหมดในเบราว์เซอร์ของคุณ ไม่มีการส่งไปยังเซิร์ฟเวอร์ จึงปลอดภัยที่จะวิเคราะห์เฮดเดอร์จริง
เฮดเดอร์ Message-ID มีไว้เพื่ออะไร?
เป็นตัวระบุเฉพาะที่กำหนดให้อีเมลแต่ละฉบับ ใช้โดยโปรแกรมอีเมลเพื่อจัดกลุ่มข้อความเป็นเธรดผ่านเฮดเดอร์ In-Reply-To ซึ่งเชื่อมโยงการตอบกลับกับ Message-ID ของข้อความต้นฉบับ
ทำไมเฮดเดอร์ Date อาจไม่ตรงกับเวลาประทับตราของเฮดเดอร์ Received?
Date ถูกตั้งค่าโดยโปรแกรมอีเมลของผู้ส่งและอาจผิดพลาดได้หากนาฬิกาของเขาไม่ตรงกัน ในขณะที่เวลาประทับตราของ Received ถูกเพิ่มโดยเซิร์ฟเวอร์ในช่วงเวลาที่ส่งจริง จึงน่าเชื่อถือกว่า